Popular searches
Hamburger Menu
//

Phishing & spear phishing simulations for your IT security

Are your employees and processes phishing-resistant? Our simulations reveal exactly where your staff, reporting processes, and technical safeguards really stand – before a real attacker finds out.

Illustration: 3 Personen und Hund in relaxter Bürosituation, davor Ritter, der mit Schild einen Drachen abwehrt.
//

The attack doesn't test your firewall. It tests your inbox.

AI makes phishing emails nearly indistinguishable from legitimate messages today. Even the most advanced security solutions reach their limits when human error is exploited – according to the BSI , one in three unwanted emails is a phishing email. Among the most active ransomware groups currently German targeting companies, clicking a phishing link is one of the most common entry points. Without clear reporting processes, a single click can quickly escalate into a company-wide incident. This is exactly where our phishing simulations come in: realistic attacks, real reactions, honest results.

//

The most common phishing methods at a glance

//

Spear phishing – when attackers know you personally

Mass phishing targets many people at once. The message is generic, the context interchangeable. Spear phishing is the opposite: a message so specifically tailored to a person or situation that it's barely recognizable as an attack.

Know your enemy: an attacker who knows your CFO is currently negotiating an acquisition doesn't need malware. A fake email with an "urgent payment approval" is enough. That's Business Email Compromise (BEC) – one of the most costly phishing variants out there.

Our spear phishing simulations start where attackers do: with Open Source Intelligence (OSINT). We collect the same information a real attacker would find and test whether your team falls for it.

//

How prepared is your team against phishing?

Let's find out together – in a controlled, safe environment with clear results.

//

The benefits of our phishing simulations

//

We make your organization more resilient against phishing

Antonia Schmalstieg

IT Security Consultant

Phishing is still underestimated in many security strategies. Security awareness often remains untapped potential, and clear reporting and response processes for suspicious emails are missing in many organizations. This is exactly where we come in: we make that potential visible and build on it deliberately.

Antonia Schmalstieg

IT Security Consultant

//

How a phishing campaign works

//

Frequently asked questions about phishing

How does spear phishing differ from mass phishing?
Spear phishing is a targeted form of phishing in which attackers approach specific individuals or organizations personally. Unlike mass phishing, it leverages personal information such as job title or current projects to make the message appear credible. This information is typically gathered from publicly available sources.
What is a phishing simulation?
A phishing simulation is a controlled, safe attack test in which realistic phishing emails are sent to employees. The goal is to train staff to recognize attacks and strengthen overall security awareness.
Why are phishing tests important for companies?
Phishing is one of the most common attack vectors in IT security. Simulations help identify and sustainably improve human, technical, and organizational weaknesses.
What are common phishing methods?
Email phishing, spear phishing, whaling, smishing, vishing, and quishing.
Are simulated phishing attacks dangerous for employees?
No. These are fully controlled and safe tests with no real malware or risks to systems or data.
How often should phishing tests be conducted?
Depending on the company, industry, and requirements, regular simulations (e.g. semi-annually or annually) are recommended to sustainably strengthen awareness and promote lasting behavior change.
Can a phishing campaign be customized?
Yes, scenarios are tailored to the industry, company size, and typical attack patterns to achieve realistic results. This often requires a prior OSINT analysis.
What is phishing awareness training?
Phishing awareness training is a security measure in which employees learn to recognize and respond to various phishing attacks through targeted training sessions.
How do phishing tests support compliance and IT security?
They help companies review security policies, document awareness levels, and meet regulatory requirements such as NIS2, BSI, and ISO 27001.

Ready for your phishing test?

You know what your security policy looks like on paper. We'll show you how it holds up under real-world conditions.

Marc Lenze

IT-Security Business Development Lead

Marc Lenze

IT-Security Business Development Lead